Differences
This shows you the differences between the selected revisions of the page.
| history 2024-02-19 | history 2026-09-11 (current) | ||
| Line 3: | Line 3: | ||
| This is a full list of changes for each release of WinSCP. See also [[project_history|Project history]] and [[incompatible_changes|Incompatible changes between versions]]. | This is a full list of changes for each release of WinSCP. See also [[project_history|Project history]] and [[incompatible_changes|Incompatible changes between versions]]. | ||
| - | ===== [[6.3]] 6.3 ((2024-02-14)) ===== | + | ===== [[6.8]] 6.8 (not released yet) ((2026-08-22)) ===== |
| - | * XML parser upgraded to Expat 2.6.0. | + | * Word wrapping in the internal editor can be toggled from toolbar menu. [[bug>2451]] |
| - | * Bug fix: Hang when prompt pops up while SFTP session is being reconnected. | + | |
| - | NOTE: Currently (2024-Feb-18), the binary executable is NOT yet signed. | + | |
| - | [[bug>2258]] | + | |
| - | ===== [[6.2.4]] 6.2.4 RC ((2024-02-03)) ===== | + | ===== [[6.6.4]] 6.6.4 (not released yet) ((2026-09-11)) ===== |
| + | |||
| + | * Increased length limit of proxy host name for updates preferences. [[bug>2456]] | ||
| + | * Optionally default to keeping Login dialog open after opening session in PuTTY. [[bug>2459]] | ||
| + | * Improving placement of widows, particularly those opened, while the main window is not visible (notably during command-line operations). | ||
| + | * Bug fix: When selecting a site to perform a command-line operation with, it was possible to select a workspace or a folder, resulting in unexpected behaviour or failure. [[bug>2457]] | ||
| + | * Bug fix: After opening session in PuTTY, WinSCP process is never closed. [[bug>2458]] | ||
| + | * Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]] | ||
| - | ··* Translations completed: Farsi, French, Japanese, Spanish and Traditional Chinese. | + | ===== [[6.6.3]] 6.6.3 RC ((2026-09-03)) ===== |
| - | * TLS/SSL core upgraded to OpenSSL 3.2.1. | + | |
| - | * WebDAV/HTTP core upgraded to neon 0.33.0. | + | |
| - | * Bug fix: Failure when trying to upload file using double-click over disconnected session. [[bug>2254]] | + | |
| - | · * Bug fix: Failure after long frequent use of session tabs. [[bug>2255]] | + | |
| - | * Bug fix: //New tab// icon is drawn incorrectly on Explorer interface with //Show selective text labels// turned off. [[bug>2257]] | + | |
| - | * Bug fix: Failure when switching to another application while new session is being opened using //New Tab// tab. [[bug>2251]] | + | |
| - | ===== [[6.2.3]] 6.2.3 RC ((2024-01-19)) ===== | + | ··* Translations completed: Belarusian, Brazilian Portuguese, Catalan, Croatian, Czech, Danish, Dutch, Finnish, French, German, Hungarian, Italian, Japanese, Korean, Lithuanian, Macedonian, Polish, Portuguese, Romanian, Russian, Serbian, Simplified Chinese, Slovak, Slovenian, Spanish, Swedish, Tamil, Traditional Chinese and Turkish. |
| + | * Some parts of GUI (panel headers, scrollbars, buttons, checkboxes) show dark in dark theme even when system-wide app theme is light. | ||
| + | * SSH core and private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. \\ It brings the following change: | ||
| + | * Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] | ||
| + | * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] | ||
| + | * Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] | ||
| + | * Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] | ||
| + | * Bundled SSH private key tools (PuTTYgen and Pageant) are 64-bit. | ||
| + | * On Windows 11, using system dark tab theme, that uses different shades for active and disabled/disconnected tabs. [[bug>2452]] | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.5.8. | ||
| + | * XML parser upgraded to Expat 2.8.4. | ||
| + | * Source code package build script supports 64-bit target. | ||
| + | * Installer upgraded to Inno Setup 6.7.3. | ||
| + | * 64-bit build is identified in version information. | ||
| + | * Resolving version of pwsh installed with MSIX. | ||
| + | * Thirdparty information from the About dialog can be copied to the clipboard even when the browser control malfunctions. | ||
| + | * Bug fix: No error is shown when connection fails. | ||
| + | * Bug fix: ''x-name'' URL parameter was incorrectly decoded. | ||
| + | * Bug fix: Incorrect number validation. | ||
| + | * Bug fix: Some controls (notably list view headers) do not correctly apply dark mode in 64-bit build. [[bug>2453]] | ||
| + | * Bug fix: 64-bit build did not identify its system to be 64-bit, what among other prevented it from identifying 64-bit COM registrations. | ||
| + | * Bug fix: Some strings use incorrect translation in 64-bit version. [[bug>2455]] | ||
| - | ··* Added new ''ca-west-1'' AWS region. | + | ===== [[6.6.2]] 6.6.2 RC ((2026-06-17)) ===== |
| - | * Translations completed: Catalan, Czech, Dutch, Finnish, German, Hungarian, Italian, Korean, Polish, Portuguese, Romanian, Russian, Simplified Chinese, Slovak, Turkish and Tamil; and updated: Japanese. | + | |
| - | * Support for ''posix-rename@openssh.com'' SFTP extension. [[bug>2231]] | + | |
| - | * When cleaning up application data, deleting even ''Martin Prikryl'' and ''WinSCP 2'' root keys, if they remain empty. | + | |
| - | * Ignoring attempts to directly move/duplicate file over itself, as if protocol requires deleting, the file would be lost. | + | |
| - | * Configurable FTP TLS shutdown procedure. [[bug>2250]] | + | |
| - | * Not failing connection when FTP server responds to ''CSID'' command with an error. [[bug>2253]] | + | |
| - | * Bug fix: Certificate authority cache was not copied to new configuration storage nor cleaned up with other caches. | + | |
| - | * Bug fix: ''ssh'' protocol URL handling was not completely unregistered. | + | |
| - | ··* Bug fix: Reported transfer size is rarely incorrect during FTP downloads. | + | |
| - | * Bug fix: Failure after connecting to server. [[bug>2251]] | + | |
| - | * Bug fix: FTP ''CSID'' command does not end with semicolon. [[bug>2252]] | + | |
| - | ===== [[6.2.2]] 6.2.2 beta ((2023-12-22)) ===== | + | ··* Experimental 64-bit version of WinSCP. [[bug>618]] |
| + | * Optionally not showing error message when connection is lost while idle. [[bug>2360]] | ||
| + | * SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.84]]. \\ It brings the following changes: | ||
| + | * Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] | ||
| + | * Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] | ||
| + | * Bug fix: spurious //"Network error: Socket is not connected"// when authenticating to some HTTP proxies. [[pbug>http-proxy-auth-wsaenotconn]] | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.5.7. | ||
| + | * XML parser upgraded to Expat 2.8.1. | ||
| + | * Restored faster C TLS/SSL AES implementation. | ||
| + | * Configurable warning when opening large file in an internal editor. [[bug>2437]] | ||
| + | * Informing that when preserving directory timestamps is enabled, using multiple connections for transfer is not possible. [[bug>2439]] | ||
| + | * Warning when pasting a session URL with unsafe settings. | ||
| + | * When opening session in PuTTY to a host for which WinSCP has multiple host keys cached, using the last key or the key that PuTTY has cached. [[bug>2440]] | ||
| + | * Always (re)registering drag&drop shell extension during installation, even when the extension is not replaced. | ||
| + | * Allowed Console interface tool to have ''.exe'' extension to avoid false positive detections by some antiviruses. [[bug>2434]] | ||
| + | * Using //"username"// and //"hostname"// as one word. | ||
| + | * Reading all system settings from 64-bit registry. | ||
| + | * Allow assigning ''null'' to ''Session.SessionLogPath''. [[bug>2438]] | ||
| + | * Avoiding using ''SSH_FXF_EXCL'' together with ''SSH_FXF_TRUNC'' SFTP file opening flags. [[bug>2444]] | ||
| + | * Optimized file system monitoring when looking for dummy directory during drag&drop downloads. [[bug>2445]] | ||
| + | * Change: Not allowing WebDAV redirects to other hosts by default. [[bug>2447]] | ||
| + | * Change: Not allowing WebDAV redirects to an unencrypted URL by default. [[bug>2448]] | ||
| + | * Updated to JCL library 2.9 commit c669fd12. | ||
| + | * Bug fix: Failure when trying to connect via HTTP proxy to FTP host with excessively long login details. [[bug>2435]] | ||
| + | * Bug fix: Buffer overflow in Console interface tool. [[bug>2436]] | ||
| + | * Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] | ||
| + | * Bug fix: Message boxes from secondary windows (like the internal editor) caused application to move to the background when when the main window was minimized. [[bug>2443]] | ||
| + | * Bug fix: Heap over-read via crafted encrypted filename. [[bug>2449]] | ||
| + | * Bug fix: Slashes in filenames can cause path traversal when invalid filename characters replacement is disabled. [[bug>2450]] | ||
| - | ··* SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.80]]. \\ It brings the following change: | + | ===== [[6.6.1]] 6.6.1 beta ((2026-04-01)) ===== |
| - | * Mitigations for SSH protocol "Terrapin" vulnerability. [[bug>2246]] [[pbug>vuln-terrapin]] | + | |
| - | * Support for ''Include'' directive when importing sites from OpenSSH. [[bug>2239]] | + | |
| - | * Change: .NET assembly collections are tagged with ''ClassInterfaceType.None'' to avoid warnings from ''regasm''. | + | |
| - | * Not using directory listing to keep FTP session alive by default. [[bug>2244]] | + | |
| - | * Windows Store installation on Windows 11 was incorrectly using INI file for configuration storage by default. [[bug>2245]] | + | |
| - | * Bug fix: Find dialog file list is scaled incorrectly on some multi monitor systems with different scaling. [[bug>2241]] | + | |
| - | * Bug fix: Cannot browse long local paths. [[bug>2242]] | + | |
| - | ===== [[6.2.1]] 6.2.1 beta ((2023-12-05)) ===== | + | ··* Support for OpenSSH ssh-agent. [[bug>1682]] |
| + | * Optionally connecting all workspace/folder sessions immediately. [[bug>1026]] | ||
| + | * Preserving panel scroll position after rename. [[bug>2425]] | ||
| + | * ''Ctrl+C'' works in list views on 'Server and protocol information' dialog. | ||
| + | * Preventing moving or copying a file or folder over ancestor folder with the same name. [[bug>2427]] | ||
| + | * WebDAV/HTTP core upgraded to neon 0.37.1. | ||
| + | * XML parser upgraded to Expat 2.7.5. | ||
| + | * Bug fix: Some menus were not working on displays to the left or above the primary display. [[bug>2423]] | ||
| + | * Bug fix: Mouse wheel downwards scrolling did not work on toolbar drop down lists. | ||
| + | * Bug fix: Once any control of permissions popup box was focused the popup no longer closed when user clicked outside of it. | ||
| + | * Bug fix: Failure when closing Transfer settings dialog with //X// button while a permissions popup box control is focused. [[bug>2420]] | ||
| + | * Bug fix: Failure when switching to a session that is being reconnected. | ||
| + | * Bug fix: Failure when the first bit of an SFTP response is set. [[bug>2422]] | ||
| + | * Bug fix: Copying to clipboard with ''Ctrl+C'' from 'Server and protocol information' was broken. | ||
| + | * Bug fix: Protocol additional information scrolling was broken. | ||
| + | * Bug fix: Master password dialog was missing //Help// button. | ||
| + | * Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] | ||
| + | * Bug fix: Wrapped settings values from Raw Site Settings dialog were not preserved. | ||
| + | * Bug fix: Some files modified by local custom command in SCP session fail to upload back. [[bug>2428]] | ||
| + | * Bug fix: Whole //Key exchange// page was incorrectly hidden when //"Handles SSH key re-exchange badly"// bug was enabled. | ||
| + | ··* Bug fix: Some message boxes leak GDI handle. [[bug>2430]] | ||
| + | * Bug fix: Login dialog leaks GDI handles. [[bug>2431]] | ||
| - | ··* File hash can be used as criterion for synchronization. [[bug>52]] | + | ===== [[6.6]] 6.6 beta ((2026-02-02)) ===== |
| - | * Consistent behavior across protocols and protocol capabilities when duplicating remote files. [[bug>2233]] | + | |
| - | * //Columns > Reset Layout// command added to Explorer interface too. | + | |
| - | * TLS/SSL core upgraded to OpenSSL 3.2.0. | + | |
| - | * Support for "Requester pays" S3 buckets. [[bug>2213]] | + | |
| - | · * Optional more prominent active session tab. [[bug>2229]] | + | |
| - | * Optionally not shortening tab titles. [[bug>2202]] | + | |
| - | · * New ''winscp.net'' root certificate. | + | |
| - | * Restored support for legacy version of the Digest algorithm specified in RFC 2069. [[bug>2109]] | + | |
| - | * Restored consistent behavior of failing, between duplicating and moving/renaming files over existing file with WebDAV protocol in scripting and .NET assembly. | + | |
| - | * When moving a folder by drag&drop to a path that already contains a subfolder with the same name, the existing folder is overwritten. | + | |
| - | * Shorter and more friendly formatting of long time intervals. [[bug>2236]] | + | |
| - | * When typing ambiguous port numbers in Login dialog, keeping the current protocol, even if it is not the default protocol for the port. | + | |
| - | * Bug fix: Failure when //New Tab// is clicked while another session is still being loaded. | + | |
| - | * Bug fix: Corrected some painting artifacts on session tabs, particularly on Windows 11. | + | |
| - | * Bug fix: ''Shift+F5'' shortcut operated with a focused file, rather than with selected files. | + | |
| - | * Bug fix: OpenSSL version in About dialog was not up to date. | + | |
| - | * Bug fix: Cannot leave directory entered via cache with SCP protocol if it was deleted meanwhile. [[bug>2234]] | + | |
| - | * Bug fix: Failure when connection is lost while reading remote directory with SFTP protocol. [[bug>2235]] | + | |
| - | * Bug fix: Multipart upload to Cloudflare R2 S3 interface fails due to too long upload ID. [[bug>2237]] | + | |
| - | * Bug fix: Panel focus was lost in some situations. | + | |
| - | * Bug fix: When S3 or WebDAV server did not provide file timestamp, downloaded file was set to oldest possible timestamp. | + | |
| - | * Bug fix: When session URL is typed into //Host name// box or pasted using context menu of the box and the Login dialog is submitted using ''Enter'' key, the URL is not parsed correctly. | + | |
| - | * Bug fix: Failure when saving edited file over reconnected session after previous reconnect attempt was aborted. [[bug>2238]] | + | |
| - | ===== [[6.2]] 6.2 beta ((2023-10-05)) ===== | + | ··* Synchronizing two local directories. [[bug>2020]] |
| - | * Single large file can be downloaded using multiple SFTP connections. [[bug>513]] | + | · * Compiler upgraded to Clang/bcc32c. [[bug>618]] |
| - | * Support for OpenSSH certificates for host verification. Sponsored by [[https://goteleport.com/|Teleport]]. [[bug>2145]] | + | * Inactive sessions can be automatically reconnected. [[bug>2232]] |
| - | ·* SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.79]]. \\ It brings the following change: | + | * Added dark theme support to: [[bug>1696]] |
| - | * Support for HMAC-SHA-512. [[pbug>hmac-sha2-512]] | + | * Login dialog. [[bug>2345]] |
| - | ·* TLS/SSL core upgraded to OpenSSL 3.1.3. | + | ···* Transfer Options dialog. |
| - | * Allowed S3 connection with IAM role instead of credentials. [[bug>2089]] | + | * Message boxes. |
| - | * Command to open the same folder as in the other panel in local file manager mode. [[bug>2189]] | + | ···* Queue column headers. [[bug>2356]] |
| - | * Support appending when streaming file contents to remote server. [[bug>2214]] | + | ···* Progress window. |
| - | * Commands to reset layout of file panels and background transfer queue list columns. | + | * Authentication Progress window. [[bug>2358]] |
| - | * Change: SSL (3.0) is no longer supported. TLS 1.0 and 1.1 are disabled by default, to match the OpenSSL 3 defaults. | + | ···* Bug fix: Scrollbar colors did not always reflect the color theme |
| - | * Using optimized OpenSSL implementations of some algorithms. | + | * Using modern directory selection dialog that scales correctly and allows creating new directory. [[bug>2373]] [[bug>2389]] |
| - | * Command to automatically size file panel columns. [[bug>2196]] | + | * Optimized GUI when working with large subdirectory selection. [[bug>2396]] |
| - | * Allowed browsing a source folder/file instead of downloading when handling a download URL. [[bug>2211]] | + | * Change: Default to UTF-8 encoding in internal editor. [[bug>2397]] |
| - | * Passing password to PuTTY using named pipe instead of commandline. | + | * New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. |
| - | * Made it harder to mis-click "never show this again" checkboxes. [[bug>2217]] | + | * TLS/SSL core upgraded to OpenSSL 3.5.5. |
| - | * ''winscp.net'' root certificate is always trusted when checking for updates, even when (corporate managed) Windows certificate store does not trust it. [[bug>2212]] | + | * WebDAV/HTTP core upgraded to neon 0.36.0. |
| - | * Not browsing a source folder when handling a download URL when a download dialog is canceled. | + | * XML parser upgraded to Expat 2.7.4. |
| - | * Recognizing ''CertificateFile'' directive when importing sites from OpenSSH. [[bug>2220]] | + | * Installer upgraded to Inno Setup 6.7.0 with dark mode support enabled. |
| - | * Restored ability to duplicate remote folders using ''cp'' command in secondary shell session even when the SFTP server supports ''copy-file''/''copy-data'' extension. [[bug>2227]] | + | * Increased WinSCP memory limit to 4 GB. [[bug>2412]] |
| - | * ''%%https://%%'' URL with ''r2.cloudflarestorage.com''; hostname is interpreted as S3 protocol, instead of WebDAV. | + | * Defined and implemented interface for the .NET library. By @mjkent. [[bug>856]] |
| - | * Recognizing path in //Host name// box on Login dialog. [[bug>2219]] | + | * Optimized TLS/SSL AES implementation. |
| - | * Improved behavior when moving/renaming over an existing folder. [[bug>2209]] | + | * Restoring ability to restart Explorer to allow upgrade of drag&drop shell extension, when installing for current user, as after-restart replacement is not possible without Administrator privileges. [[bug>2381]] |
| - | * Improved OpenSSH ''config'' file parsing, particularly quoted and escaped values. [[bug>2206]] | + | * MSI toolset updated to WiX 5. |
| - | * Support for ProFTPD command ''%%OPTS REST STOR%%'' to query if upload restart is possible. [[bug>2194]] | + | * Commands to copy paths to the clipboard on the Synchronization checklist window. |
| - | * Not showing a filter mask on a disconnected panel. | + | * Cryptography optimization. |
| - | * Implemented generic ''ICollection'' implicitly by .NET assembly collections. [[bug>2187]] | + | ··* Support long AWS/S3 session tokens. [[bug>2403]] |
| - | * ''ProxyMethod'' raw session setting supports symbolical value names. | + | * Prevent hang when new device is attached or removed while some mapped network drive is not available. [[bug>2382]] |
| - | * Ignoring disconnects from the server while closing the connection. [[bug>2195]] | + | * Copy and paste improvements: |
| - | * Translations updated: Danish and Traditional Chinese. | + | ····* Consistently renaming local files dropped or pasted back to their source directory to avoid collisions. |
| - | ··* Preventing background transfer queue list columns width to shrink too much. [[bug>2208]] | + | ····* Bug fix: When copying local files to clipboard from system context menu, "cut" state of previously cut files was not cleared. |
| - | * Not forcing text mode for edits with Windows Notepad on Windows 10 1809 and newer, as it already supports non-Windows line endings. | + | * Not redundantly verifying WebDAV or S3 certificate in Windows Certificate store if it is already marked as trusted in session settings. [[bug>2404]] |
| - | * Allowed disabling SFTP extension use. [[bug>2222]] | + | * Provide SNI when opening FTP data connection. [[bug>2410]] |
| - | * Using packet size limit announced by OpenSSH ''limits@openssh.com'' extension. | + | * Optimized synchronization checklist sorting. |
| - | * Improved HTTP error reporting and logging. | + | * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] |
| - | * With application logging enabled, automatic updates installation is started with logging too. | + | * Convert unsupported SSH proxy to SSH tunnel when importing site from PuTTY. [[bug>2408]] |
| - | * Throwing an exception when ''Session.SessionLogPath'' is set to a path with invalid ''.xml'' extension. [[bug>2215]] | + | * FTP directory listing falls back to the other active/passive mode, consistently with file transfers. |
| - | * Recognizing IP addresses starting with zero in FTP PASV response as unroutable. [[bug>2224]] | + | * Consistently calling command to open window with specific directory //Explore//, instead of sometimes //Browse//. |
| - | * When there is both administrative and non administrative installation, automatic update automatically selects the the correct one for update. | + | * Consistently referring to file last modification timestamp column as //Date modified//. |
| - | ··* Not displaying Administrator shield icon on //Upgrade// button, when Administrator permissions are not needed for the upgrade. | + | * With INI file provided on command-line, using the same INI file when starting a new instance. |
| - | * More meaningful error message when credentials are missing in scripting and .NET assembly. | + | * Windows shell local file copy status window is centered on the main window. |
| - | * Bug fix: WebDAV or S3 certificate that is recognized by Windows Certificate store, but have other issues, cannot be marked trusted by the user. [[bug>2191]] | + | * Made taskbar flashing configurable in GUI. [[bug>2411]] |
| - | * Bug fix: Localized HTTP connection error messages are incorrectly decoded. [[bug>2197]] | + | * Control labels on transfer settings dialogs do not show keyboard accelerator cue, until ''Alt'' key is pressed. |
| - | * Bug fix: Special characters in directory names were not correctly restored when uploading on background with multiple connections for single transfer enabled. | + | * Not using drag images even with directory trees. [[bug>1274]] |
| - | * Bug fix: Master password prompt was not added to taskbar when opening session from commandline or when automatically loading workspace to yet invisible main window. | + | * Allow configuring checksum commands. [[bug>2394]] |
| - | * Bug fix: Handling download URL does not work when another idle instance is running. [[bug>2203]] | + | * Updated to JCL library 2.8.1. |
| - | * Bug fix: TLS session resumption is not working for subsequent FTP data connections with TLS 1.3 with some servers. [[bug>2210]] | + | * Updating jump list only when running with GUI. |
| - | * Bug fix: Failure when using ''/browse='' switch and a file panel is empty. | + | * Made space on permissions box for longer translations. [[bug>2398]] |
| - | * Bug fix: Correcting default OpenSSL configuration paths. | + | * Opening //Default Apps// //Settings// page directly to open it in the foreground and avoid flashing //Control Panel// window. |
| - | * Bug fix: Potential failure when opening unencrypted HTTP/WebDAV connection. | + | * Improving order in which Windows Narrator reads window controls. |
| - | * Bug fix: When second local panel tree view has focus, some keyboards shortcuts still operated on the first local panel. | + | * All edit boxes with history consistently do not auto complete and show 16 entries in the drop down. |
| - | * Bug fix: Local file panel malfunctions when it starts on a drive hidden by Explorer's policy. [[bug>2216]] | + | * Removed obsolete //Preserve remote timestamp// session settings. |
| - | * Bug fix: When opening UNC path, the network drive is not added to the other local panel directory tree. | + | * Bug fix: Local file with invalid characters replaced could not be explored from the Synchronization checklist window. |
| - | * Bug fix: When opening the UNC path on the second local panel, the network drive is not added to drive drop-down menus. | + | * Bug fix: Files modified by local custom command are not always uploaded to the correct remote directory. [[bug>2370]] |
| - | * Bug fix: Script sometimes does not abort after receiving no answer for prompt, when running in batch mode. | + | * Bug fix: List of network drives in drive drop down and directory tree did not always match. |
| - | * Bug fix: Configuration reading was broken after an attempt to access a non-existing sub-section within a section existed in raw configuration only. | + | * Bug fix: Host key prompt did not have the default button. |
| - | * Bug fix: WinSCP could ask the server to return more data during SFTP download than it can process. [[bug>2218]] | + | * Bug fix: When the local path specified on Open directory/Location profile dialog is not existing, when browsing for a new path, the trailing part of the nonexisting path was appended to the new path. |
| - | * Bug fix: Renaming tab invalidated remembered password. | + | * Bug fix: Trying to enter an invalid link in local panel fails silently. |
| - | * Bug fix: WinSCP loses focus after custom command is executed. [[bug>2221]] | + | * Bug fix: After FTP data connection fails to open further use of the session is broken. |
| - | * Bug fix: Some DLLs were not protected against hijacking. [[bug>2223]] | + | * Bug fix: Pasting cut files from the clipboard into a local panel copies them instead of moving them. [[bug>2400]] |
| - | * Bug fix: Failure when error occurs on secondary shell session with //Continue on error// option enabled. [[bug>2226]] | + | * Bug fix: Some edits did not save their value to history when submitting with ''Enter''. |
| - | * Bug fix: Failure when reconnect on edited/opened file save is canceled. [[bug>2228]] | + | * Bug fix: Too long edit history dropdown can overflow monitor bounds. [[bug>2432]] |
| + | * Bug fix: Message box texts and some control labels are not visible to screen readers. [[bug>2413]] | ||
| + | * Bug fix: Failure when clicking tab close button while the session is already being closed. [[bug>2416]] | ||
| - | ===== [[6.1.2]] 6.1.2 ((2023-09-19)) ===== | + | ===== [[6.5.9]] 6.5.9 (not released yet) ((2026-09-10)) ===== |
| - | * MSI installer is not localized anymore to avoid problems with GPO. [[bug>2200]] | + | * Back-propagated fixes from 6.6.4 release: |
| - | * TLS/SSL core upgraded to OpenSSL 1.1.1w. | + | ···* Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]] |
| - | * Translations updated: Catalan, Danish, Russian and Turkish. | + | |
| - | ·* Added new ''il-central-1'' AWS region. | + | |
| - | * Bug fix: Typo in GPL license in installer. [[bug>2201]] | + | |
| - | * Bug fix: Check for application updates was limited to TLS 1.2. | + | |
| - | ===== [[6.1.1]] 6.1.1 ((2023-06-21)) ===== | + | ===== [[6.5.8]] 6.5.8 ((2026-09-10)) ===== |
| - | * Translations completed: Brazilian Portuguese, Farsi and Portuguese; and updated: French and Italian. | + | * This is Microsoft Store-only release that fixes packaging problem of 6.5.7. The actual binaries are still 6.5.7. |
| - | * Support for file masks in //Keep local directory up to date// extension. [[bug>1892]]. | + | ···* Bug fix: Cannot install from Microsoft Store because of invalid 'sr' language. [[bug>2460]] |
| - | * TLS/SSL core upgraded to OpenSSL 1.1.1u. | + | |
| - | ·* Bug fix: Patterns in default values of extension options were escaped in an extension tooltip. | + | |
| - | * Bug fix: //Calculate Directory Sizes// command was redundantly in all local panel column context menus. | + | |
| - | * Bug fix: Thanks and transitioning help toolbar message in Store installation was not readable in Dark theme. [[bug>2198]] | + | |
| - | ··* Bug fix: MSI installer runs in Catalan language (or possibly fails) when used in GPO. [[bug>2199]] | + | |
| - | ===== [[6.1]] 6.1 ((2023-05-23)) ===== | + | ===== [[6.5.7]] 6.5.7 ((2026-09-09)) ===== |
| - | * Translations completed: Catalan, Czech, Dutch, Finnish, French, German, Hungarian, Italian, Japanese, Korean, Polish, Romanian, Russian, Simplified Chinese, Spanish, Swedish and Turkish. | + | * Translations completed: Croatian, Finnish, Georgian, Italian and Serbian, and updated: Slovenian. |
| - | * Consistently open the nearest existing parent folder when the current local panel directory is deleted. [[bug>2182]] | + | * TLS/SSL core upgraded to OpenSSL 3.3.7. |
| - | * Visual feedback when control (drop down list particularly) is focused via keyboard accelerator. | + | * SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. SSH core upgraded to include some fixes. \\ It brings the following change: |
| - | ·* Building .NET assembly in Visual Studio 2022. | + | ···* Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] |
| - | ·* Bug fix: Remote file pasted to an external HDD is downloaded twice. [[bug>2183]] | + | ···* Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] |
| - | ·* Bug fix: Callstack debug logging in .NET assembly was broken. | + | ···* Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] |
| - | ·* Bug fix: Corrected hint for //Default// session color command. | + | ···* Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] |
| - | * Bug fix: When reading input ''Stream'' in .NET assembly upload fails in 64-bit process, the transfer is not interrupted. | + | * Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] |
| - | ·* Bug fix: Failure when application log cannot be opened. [[bug>2186]] | + | ···* Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] |
| - | * Bug fix: Work around key algorithm naming change in OpenSSH 7.7 and older (from pre-release of PuTTY 0.79). [[bug>2188]] | + | * Back-propagated fixes from 6.6.2 beta release: |
| - | * Bug fix: With debug logging enabled, the echoed script commands and XML log group names miss the command name. | + | ···* Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] |
| + | * Bug fix: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. CVE-2026-45447 fix from OpenSSL 3.4.6. | ||
| - | ===== [[6.0.2]] 6.0.2 RC ((2023-04-18)) ===== | + | ===== [[6.5.6]] 6.5.6 ((2026-03-25)) ===== |
| - | * When saving edited/opened file, optionally warning if it was modified meanwhile externally. [[bug>99]] | + | * Translations completed: Macedonian, and updated: Lithuanian, and Russian. |
| - | * Autoreconnecting a disconnected session when saving an edited file. [[bug>1858]] | + | * TLS/SSL core upgraded to OpenSSL 3.3.6. |
| - | * Even user-disconnected sessions can be reconnected when saving files opened from them. | + | * Back-propagated improvements from 6.6–6.6.1 beta release: |
| - | * Allowed reads with non-zero offsets with stream returned by ''Session.GetFile''. [[bug>2181]] | + | ···* New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. |
| - | * ''puttygen'' switches ''%%--new-passphrase%%'' and ''%%--old-passphrase%%'' are recognized. | + | ···* XML parser upgraded to Expat 2.7.5. |
| - | ··* Bug fix: When switching from a remote tab to a local tab, the "right" status bar does not show correct information. | + | ···* Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] |
| - | * Bug fix: //Edit Link// command in Explorer interface has incorrect name //Link//. | + | ···* Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] |
| - | ·* Bug fix: //Mark > Select/Unselect// command was behaving incorrectly. | + | |
| - | * Bug fix: HTTP proxy authentication prompt was not localized. | + | |
| - | ·* Bug fix: Directory tree does not adjust line height to custom panel font size. [[bug>2172]] | + | |
| - | * Bug fix: Green artifacts at partial file icon overlay. | + | |
| - | ·* Bug fix: The first copy&paste or drag&drop of remote files to other application might fail in Explorer interface. [[bug>2175]] | + | |
| - | ·* Bug fix: Temporary directory is left behind when WinSCP is closed while it has some remote files copied to the clipboard. [[bug>2176]] | + | |
| - | * Bug fix: ''Session.EnumerateRemoteFiles'' does not work correctly when the mask includes brackets and other symbols. [[bug>2177]] | + | |
| - | * Bug fix: Location profiles should not be used unless the session is connected. | + | |
| - | ===== [[6.0.1]] 6.0.1 beta ((2023-03-07)) ===== | + | ===== [[6.5.5]] 6.5.5 ((2025-11-19)) ===== |
| - | * //Compare Directories// command is available in local file manager mode. | + | * Translation updated: Vietnamese. |
| - | * Installer upgraded to Inno Setup 6.2.2. | + | * Bug fix: Pasting files using local directory tree context menu pastes them to the current directory, instead of the selected one. |
| - | * Translations updated: German and Hungarian. | + | * Bug fix: Failure when opening site imported from PuTTY with unsupported SSH proxy. [[bug>2407]] |
| - | * Renamed //File// menu in Explorer interface to //Files// for consistency with Commander interface. | + | * Bug fix: Incorrect hostname validation when connecting to S3 endpoint with certificate that does not cover root S3 hostname. [[bug>2409]] |
| - | * Using plural //Tabs// for consistency with other menus. | + | |
| - | * Using the same timestamp format in local and remote file panels. | + | |
| - | * Option to allow box-drawing characters to render correctly in an Internal editor. [[bug>2169]] | + | |
| - | * Bug fix: Failure when selecting S3 protocol in Login dialog with non-existing ''.aws/credentials'' file. [[bug>2166]] | + | |
| - | * Bug fix: Tab close button of new session was drawn as clicked, if it was opened from Login dialog popped up after the last session was closed by clicking its close button. | + | |
| - | * Bug fix: Rename tab dialog still says //"Rename session"//. | + | |
| - | * Bug fix: Generated code uses obsolete ''SessionOptions.WebdavSecure'' property instead of current ''SessionOptions.Secure''. | + | |
| - | * Bug fix: Generated code for unsecure S3 protocol does not include ''SessionOptions.Secure'' property. | + | |
| - | * Bug fix: Separation of //Tab// and //Session// menus was unintentionally not reverted for Explorer interface. | + | |
| - | * Bug fix: Wrong behaviour when trying to open a workspace that does not contain any valid session. | + | |
| - | * Bug fix: ''Ctrl+T'' opens the wrong type of tab. | + | |
| - | * Bug fix: The ''!K'' and ''!\'' custom command and PuTTY patterns were not included in syntax hint. | + | |
| - | * Bug fix: Hang when FTP directory listing contains nul character. [[bug>2167]] | + | |
| - | * Bug fix: //Parent directory// command was missing its keyboard shortcut in the menu. | + | |
| - | * Bug fix: Workspace could not be saved when the active tab was not connected or was local. | + | |
| - | * Bug fix: Some control labels were showing keyboard accelerators without keyboard intervention. | + | |
| - | * Bug fix: Pressing ''Alt'' with some combo boxes focused did not show keyboard accelerators. | + | |
| - | * Bug fix: Failure when starting with colored session. [[bug>2168]] | + | |
| - | ===== [[6.0]] 6.0 beta ((2023-02-08)) ===== | + | ===== [[6.5.4]] 6.5.4 ((2025-10-16)) ===== |
| - | * Local file manager mode (two local panels). [[bug>1893]] | + | |
| - | · * Windows 11 flat style graphics. | + | |
| - | * SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.78]]. It brings the following changes: | + | |
| - | * Support for OpenSSH certificates (for user authentication keys). [[bug>1873]] [[pbug>ssh2-openssh-certkeys]] | + | |
| - | * Support for NTRU Prime post-quantum key exchange. [[pbug>ntru]] | + | |
| - | * Support for AES-GCM (in the OpenSSH style rather than RFC 5647, without hardware acceleration). [[pbug>aes-gcm]] | + | |
| - | * Support for more forms of Diffie-Hellman key exchange: new larger integer groups (such as group16 and group18), and support for using those and ECDH with GSSAPI. [[pbug>rfc8268-dh-groups]] [[pbug>gss-key-exchange-more-algs]] | + | |
| - | * Ongoing delete operation can be moved to background queue. [[bug>194]] | + | |
| - | * New DigiCert EV code signing certificate valid until February 2026 is used for signing binaries. | + | |
| - | * Showing directory size in file panel. [[bug>41]] | + | |
| - | * MSI installation package. [[bug>83]] | + | |
| - | * TLS/SSL core upgraded to OpenSSL 1.1.1t. | + | |
| - | * Translations updated: German and Russian. | + | |
| - | * File checksum calculation support for SCP protocol and SFTP protocol via secondary shell session using shell commands like ''sha256sum''. | + | |
| - | * Tab titles are shortened to fit window width as needed. [[bug>1423]] | + | |
| - | * AWS S3 profile selection. [[bug>2057]] | + | |
| - | * Consistent behavior across protocols when renaming/moving remote files: [[bug>2120]] | + | |
| - | * Asking before overwriting existing files, both for renaming/moving. | + | |
| - | * Allowing overwriting existing files even with protocols that require deleting the existing file first and with WebDAV. | + | |
| - | * Change: In scripting and .NET assembly, moving a file over an existing file will overwrite the existing file. [[bug>2185]] | + | |
| - | * Using SFTP ''copy-data'' extension to duplicate remote files with servers that do not support ''copy-file'' extension (OpenSSH). | + | |
| - | · * Allowed scrolling of background transfers queue list view while dragging a transfer. [[bug>2154]] | + | |
| - | * Tabs show tooltips with full session name, username, hostname and paths. | + | |
| - | * Displaying thanks and transitioning help toolbar message after Store installation over classic installation. | + | |
| - | * Remembering remote directory tree nodes state when switching sessions. [[bug>1057]] | + | |
| - | * Progress animations for //Duplicate// and //Move To// operations. | + | |
| - | * Download edited/opened files with up-to-date timestamps. [[bug>2122]] | + | |
| - | * Displaying current version on the New version notification. [[bug>2125]] | + | |
| - | * Support for S3 servers without TLS encryption. [[bug>1995]] | + | |
| - | * Support for redirected WebDAV downloads (even to other hosts). [[bug>1667]] | + | |
| - | * Optionally reading password from a file. [[bug>2102]] | + | |
| - | * Input files can be read from named pipes. [[bug>2118]] | + | |
| - | * ''Shift''-clicking //New Session// command opens the Login dialog in new WinSCP instance, instead of possibly opening new instance of workspace. | + | |
| - | * Option to always sort directories by name. [[bug>1024]] | + | |
| - | * Bookmark drop-down menu in Explorer interface. [[bug>2127]] | + | |
| - | * Preserving changed passwords of ad-hoc sessions in workspace. [[bug>2128]] | + | |
| - | * In file panel, file sorting by date and size is by default descending even when initiated by menu, toolbar or keyboard shortcut, consistently with sorting by clicking panel column header. | + | |
| - | * Allowed opening all sites in a folder in PuTTY. [[bug>2079]] | + | |
| - | * Allowing environment variables in custom INI file path. [[bug>2105]] | + | |
| - | * Private key pattern ''!K'' in PuTTY command-line and custom commands. [[bug>2107]] | + | |
| - | * Automatically reconnect when FTP server fails to open data connection with ''426'' code, if it previously worked. [[bug>2110]] | + | |
| - | * Cleaning up temporary WinSCP PuTTY sessions. | + | |
| - | * Clearing environment variables ''BLOCK_SIZE'' and ''LS_BLOCK_SIZE''. [[bug>2129]] | + | |
| - | * Added import from KiTTY directly to the Import dialog. [[bug>1551]] | + | |
| - | * Warn when user selects too verbose logging level that degrades performance. [[bug>2155]] | + | |
| - | * Contents of About dialog can be copied to the clipboard using ''Ctrl+C''. | + | |
| - | * Blocking Windows Rich Edit formatting keyboard shortcuts in Internal editor. [[bug>2108]] | + | |
| - | * WebDAV/HTTP core upgraded to neon 0.32.5. | + | |
| - | * PNG code upgraded to PngComponents 1.9.0. | + | |
| - | * When switching tabs, prevent visibly scrolling the panels when focusing the last selected file. | + | |
| - | * Removed the "compression" indicator from the status bar. | + | |
| - | * Added GSSAPI key exchange algorithms to ''/info''. | + | |
| - | * Allowed normal behavior of double-click on a file even when resolving of symlinks is disabled. [[bug>2037]] | + | |
| - | * Change: ''SessionOptions.WebdavSecure'' renamed to ''SessionOptions.Secure'' (and applies to S3 protocol too). | + | |
| - | * ''Session.ExecutablePath'' returns detected or actual executable path when not set. [[bug>2055]] | + | |
| - | * Change: Keyboard shortcut for //Command Line// command changed to ''Shift+Ctrl+M'' (''Shift+Ctrl+N'' previously). | + | |
| - | * Do not overwrite existing local file when FTP download fails to start. [[bug>2132]] | + | |
| - | * Preventing construction of .NET assembly internal collection classes, what avoids them being unnecessarily registered for COM. | + | |
| - | * Hidden configuration option to increase maximal number of background transfers at the same time. [[bug>2117]] | + | |
| - | * Not animating taskbar button, when items are queued, but processing is disabled | + | |
| - | * Removed gap in initial toolbar layout. | + | |
| - | * Better formatting of feature list on Interface page of Preferences dialog. | + | |
| - | * Optimizing adjusting to updated system font. [[bug>2149]] | + | |
| - | * Consistency with loading icons synchronously and on the background. [[bug>2161]] | + | |
| - | * Added new ''ap-southeast-4'' AWS region. | + | |
| - | * Selecting the best language with each installation. [[bug>2160]] | + | |
| - | * Workaround for using ''/ini=nul'' on systems when reading ''nul'' file fails. [[bug>2163]] | + | |
| - | * Support for FTP ''CSID'' command. | + | |
| - | * Not logging supported SFTP extensions included directly in ''SSH_FXP_VERSION'' response as unknown. | + | |
| - | * Bug fix: Failure when trying to switch session tabs while previous switch did not complete yet. | + | |
| - | * Bug fix: When importing from FileZilla with KiTTY selected as SSH terminal, host keys were imported from KiTTY instead of FileZilla/PuTTY. | + | |
| - | * Bug fix: Incorrect escaping of values in single-quoted patterns in custom commands. | + | |
| - | * Bug fix: Configuration does not load when using ''/rawconfig'' command-line switch and read-only configuration sections. | + | |
| - | * Bug fix: When file rename fails, wrong part of filename might be selected in the inline filename editor. | + | |
| - | * Bug fix: Mouse cursor flickers while retrieving remote file properties. | + | |
| - | * Bug fix: Using any keyboard shortcut with ''Alt'' key shows menu keyboard accelerators permanently. | + | |
| - | * Bug fix: Session tabs cannot be dragged when the user has mouse buttons swapped. | + | |
| - | * Bug fix: The //"Keep temporary copies of remote files in deterministic paths"// option applied when duplicating remote files via a local temporary copy and with custom commands, breaking their functionality. [[bug>2140]] | + | |
| - | * Bug fix: S3 credentials checkbox on Login dialog had wrong tab order. | + | |
| - | * Bug fix: Turned-off keepaliaves are not propagated to PuTTY. [[bug>2141]] | + | |
| - | * Bug fix: With password storing administratively disabled, the ''/rawsettings'' switch cannot be used to set passwords. [[bug>2142]] | + | |
| - | * Bug fix: Focus was lost after checking for updates. | + | |
| - | * Bug fix: Failure on startup fatal error. | + | |
| - | * Bug fix: Error when uploading file sized just below 32 kB boundary to FTP server over TLS 1.3. [[bug>2019]] | + | |
| - | * Bug fix: Failure when doing agent forwarding with Pageant 0.74 or older. [[bug>2162]] | + | |
| - | * Bug fix: Pressing ''Tab'' during incremental search on Login dialog never look into collapsed folders when more than one visible node matched the search. | + | |
| - | * Bug fix: File on local network share treated as folder when uploading. [[bug>2056]] | + | |
| - | * Bug fix: Failure when parsing FTP checksum response misses the actual response. | + | |
| - | ===== [[5.21.8]] 5.21.8 ((2023-04-11)) ===== | + | ··* Translations updated: Belarusian and Georgian. |
| - | + | · * TLS/SSL core upgraded to OpenSSL 3.3.5. | |
| - | * Back-propagated fixes from 6.0 beta release: | + | * XML parser upgraded to Expat 2.7.3. |
| - | ···* Translations updated: German, Hungarian and Russian. | + | · * Added new ''ap-southeast-6'' AWS region. |
| - | ···* TLS/SSL core upgraded to OpenSSL 1.1.1t. | + | * Bug fix: When restored after operation completed while minimized the window is disabled. [[bug>2393]] |
| - | ···* Updated links to online help. | + | * Bug fix: Command ''md5sums'' is incorrectly used to calculate MD5 checksum instead of ''md5sum''. [[bug>2392]] |
| + | ·* Bug fix: Incomplete FTP upload when the source stream/stdin reads less than requested. [[bug>2395]] | ||
| + | ·* Bug fix: ''Shift''-clicking //OK// button on Synchronization checklist window when synchronization in the background was not possible still closed the window. | ||
| + | ··* Bug fix: Failure after reloading file panel when number of files decreases. [[bug>2402]] | ||
| + | ·* Bug fix: Failure or silently missing headers when when S3 request headers were too long. | ||
| [[history_old|Older versions]] | [[history_old|Older versions]] | ||
| ~~NOTOC~~ | ~~NOTOC~~ | ||
| ~~ARCHIVE=history_old~~ | ~~ARCHIVE=history_old~~ | ||